First published: Mon Sep 10 2012(Updated: )
`security/__init__.py` in MoinMoin 1.9 through 1.9.4 does not properly handle group names that contain virtual group names such as "All," "Known," or "Trusted," which allows remote authenticated users with virtual group membership to be treated as a member of the group.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Moinmo Moinmoin | =1.9.0 | |
Moinmo Moinmoin | =1.9.1 | |
Moinmo Moinmoin | =1.9.2 | |
Moinmo Moinmoin | =1.9.3 | |
Moinmo Moinmoin | =1.9.4 | |
pip/moin | >=1.9<1.9.5 | 1.9.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.